Summary
The Bundesamt für Sicherheit in der Informationstechnik (BSI), or the Federal Office for Information Security, is the national cybersecurity authority of Germany. The BSI is responsible for protecting the German government's IT and communications infrastructure, advising on cybersecurity matters, and setting security standards across both public and private sectors in Germany.
Red Hat has published Guidance to ensure that your OCP deployment complies with BSI IT-Grundschutz blocks SYS.1.6 Containerization and APP.4.4 Kubernetes.
Built-in compliance capabilities
Red Hat products have built-in capabilities that help you to align with the BSI policy. By using integrations with the system management solutions available in our portfolio, you can align the configuration of the machine with the requirements. However, the result is not full compliance - you always need to review the results and take the context of your specific deployment into account.
Red Hat Enterprise Linux
You can install the system already pre-configured to BSI Building Blocks SYS.1.1 and SYS.1.3 by using RHEL image builder:
Note that this is integrated also in the Red Hat Insights, linked below.
If you prefer a kickstart-based installation, the method is described in the RHEL security guide:
You can build and deploy hardened bootable images pre-configured to BSI Building Blocks SYS.1.1 and SYS.1.3 for RHEL Image mode:
You can check the system configuration during runtime by using the OpenSCAP command-line tool:
Red Hat Satellite
You can plan and configure compliance policies, deploy the policies to hosts, and monitor the compliance of your hosts in Red Hat Satellite. For more information, see the product documentation:
Red Hat Insights for RHEL
You can create and manage your custom security policies entirely within the compliance service UI, as well as monitor the compliance state of your systems, remediate any discrepancies, and use the custom security policies in image builder to deploy additional systems:
Red Hat OpenShift
A validated and supported compliance automation profile for BSI is also available with the Compliance Operator
Products in Scope
- Red Hat OpenShift
- 4
- Red Hat Enterprise Linux
- 9
Additional Resources
Meta Data
Products
Regions
Industries